{"id":208902,"date":"2025-09-15T09:30:41","date_gmt":"2025-09-15T13:30:41","guid":{"rendered":"https:\/\/nationalcybersecuritysociety.org\/?p=208902"},"modified":"2025-11-12T15:44:14","modified_gmt":"2025-11-12T20:44:14","slug":"ctw-17-march-2025","status":"publish","type":"post","link":"https:\/\/nationalcybersecuritysociety.org\/?p=208902","title":{"rendered":"CTW #17 \u2014 March 2025"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;||13px|||&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_image src=&#8221;https:\/\/nationalcybersecuritysociety.org\/wp-content\/uploads\/2025\/09\/NCSS-3397-Bulletin-Header-Footer-Header-Graphic-1600&#215;350-Compressed.png&#8221; title_text=&#8221;NCSS-3397-Bulletin-Header-Footer-Header Graphic 1600&#215;350-Compressed&#8221; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p><em>Published: March 14, 2025<\/em><\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p><span>Our new bulletin <strong><em>Cyber Threat Watch<\/em><\/strong> has been created to help small businesses stay up to date on the latest threats, news, and events affecting their business. The content has been curated to make cybersecurity easy and accessible for both technical and nontechnical readers.<\/span><\/p>\n<p>[\/et_pb_text][et_pb_heading title=&#8221;Featured Cyber News \u2014 Cybersecurity Maturity Model Certification (CMMC)&#8221; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; title_level=&#8221;h2&#8243; title_font=&#8221;|600|||||||&#8221; title_text_color=&#8221;#00688E&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_heading][et_pb_image src=&#8221;https:\/\/nationalcybersecuritysociety.org\/wp-content\/uploads\/2025\/09\/AdobeStock_925689897-scaled.jpeg&#8221; title_text=&#8221;Compliance. Hand holding a globe with network connecting data. In the context of digital technology, compliance with data regulations is essential for maintaining security and trust in global networks&#8221; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p>With the latest updates to the Cybersecurity Maturity Model Certification (CMMC) 2.0 in October 2024, compliance will soon be essential for any organization seeking to work with the U.S. Department of Defense (DoD). However, these cybersecurity standards are not limited to U.S. companies\u2014organizations worldwide that provide services to the DoD or are part of its supply chain must also meet the CMMC compliance requirements.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&#8221;1_3,2_3&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;0px||0px|||&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;1_3&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_image src=&#8221;https:\/\/nationalcybersecuritysociety.org\/wp-content\/uploads\/2025\/09\/AdobeStock_654739539-scaled.jpeg&#8221; title_text=&#8221;United States Department of Defense headquarter logo&#8221; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][\/et_pb_column][et_pb_column type=&#8221;2_3&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; header_3_text_color=&#8221;#00688E&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h3>What is CMMC 2.0?<\/h3>\n<p>The CMMC 2.0 is a cybersecurity framework that ensures businesses working with the DoD have the necessary safeguards to protect <span><a href=\"https:\/\/isoo.blogs.archives.gov\/2020\/06\/19\/%E2%80%8Bfci-and-cui-what-is-the-difference\/\">Federal Contract Information (FCI) and Controlled Unclassified Information (CUI)<\/a><\/span>.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;0px||0px|||&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;21px|||||&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p>FCI includes government contract-related data that isn\u2019t publicly available and requires basic security protections under <span><a href=\"https:\/\/www.acquisition.gov\/far\/52.204-21\">FAR 52.204-21<\/a><\/span>. On the other hand, CUI is marked or identified as sensitive information requiring protection under the CUI program, which enforces stricter safeguards by following <span><a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/171\/r3\/final\">NIST SP 800-171<\/a><\/span> security controls\u2014this means that the government entity seeking private sector services or products is responsible for identifying what qualifies as CUI. Therefore, all CUI is FCI, but not all FCI is CUI. If your business\u2019s services or products may fall under CUI, ask the DoD program manager who is responsible for the contract to confirm what applies.<\/p>\n<p>First introduced in 2021, it wasn\u2019t a contract requirement at that time. However, the Final Rule (October 2024) has made the CMMC compliance mandatory. This means that businesses will have to comply with the new requirements, once implemented, to secure new contracts, renew existing ones, or continue working with the DoD.<\/p>\n<p>[\/et_pb_text][et_pb_image src=&#8221;https:\/\/nationalcybersecuritysociety.org\/wp-content\/uploads\/2025\/09\/AdobeStock_512641198-scaled.jpeg&#8221; title_text=&#8221;automatic coordinate measurement machine (CMM) during inspection automotive or motorcycle industrial part in quality control manufacturing process&#8221; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; header_3_text_color=&#8221;#00688E&#8221; custom_css_free_form=&#8221;ol {||  list-style: none !important; ||  counter-reset: item; ||}||||ol li {||  counter-increment: item; ||  position: relative; ||  padding-left: 2em; \/* Adjust as needed for spacing *\/||}||||ol li::before {||  content: counter(item) %22.%22; ||  font-weight: bold; ||  position: absolute;||  left: 0; ||  width: 1.5em; ||  text-align: right;||}&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h3>Key Changes in the Latest Version<\/h3>\n<p><span>The latest update to CMMC 2.0 has simplified compliance while strengthening cybersecurity. Here\u2019s what\u2019s new:<\/span><\/p>\n<ul>\n<li><strong><span>Three Levels of Certification (reduced from five):<\/span><\/strong><span><br \/>&#8211; <a href=\"https:\/\/ndisac.org\/dibscc\/cyberassist\/cybersecurity-maturity-model-certification\/level-1\/\">Level 1<\/a> (foundational; self-assessed): Basic security requirements for FCI<\/span><span><br \/>&#8211; <a href=\"https:\/\/ndisac.org\/dibscc\/cyberassist\/cybersecurity-maturity-model-certification\/level-2\/\">Level 2<\/a> (advanced; self-assessed, or assessed by the C3PAO\u2013<em>Certified Third-Party Assessor Organization<\/em>): Protection of CUI, aligned with NIST SP 800-171<\/span><span><br \/>&#8211; <a href=\"https:\/\/ndisac.org\/dibscc\/cyberassist\/cybersecurity-maturity-model-certification\/level-3\/\">Level 3<\/a> (expert; assessed by the DIBCAC\u2013<em>Defense Industrial Base Cybersecurity Assessment Center<\/em>): Highest level of security required for critical DoD systems, with additional requirements from <a href=\"https:\/\/csrc.nist.gov\/news\/2021\/nist-publishes-sp-800-172\">NIST SP 800-172<\/a><\/span><\/li>\n<li><strong><span>Self-Assessments and Affirmations:<\/span><\/strong><span> Companies at Level 1 and some Level 2 contracts can self-certify annually, but a senior official must sign off on compliance.<\/span><\/li>\n<li><strong><span>Enforced Through Contracts:<\/span><\/strong><span> CMMC is a condition of contract eligibility, which means that companies must meet its requirements to secure or maintain DoD contracts.<\/span><\/li>\n<\/ul>\n<h3><span>Who Needs to Comply?<\/span><\/h3>\n<p><span>The CMMC requirements apply to all businesses that work within the DoD supply chain, including the following:<\/span><\/p>\n<ol>\n<li><strong> <\/strong><strong><span>Prime Contractors:<\/span><\/strong><span> Businesses that directly contract with the DoD<\/span><\/li>\n<li><strong><span>Subcontractors:<\/span><\/strong><span> Businesses that support prime contractors in any capacity<\/span><\/li>\n<li><strong>Third-Party Service Providers:<\/strong> Businesses that process, store, or transmit FCI or CUI as third-party providers to DoD contractors<\/li>\n<li><strong>Non-U.S. Organizations:<\/strong> Businesses overseas that contract with the DoD or handle FCI or CUI within the DoD supply chain<\/li>\n<\/ol>\n<h3>Three-Year Implementation Plan: What Small Businesses Need to Know<\/h3>\n<p><span>The requirements of the CMMC 2.0 <\/span>Final Rule (32 CFR part 170) <span>will roll out over three years, starting 60 days after the publication of the 48 CFR part 204 acquisition rule, which is expected by mid-2025. Here\u2019s what to expect:<\/span><\/p>\n<ul>\n<li><strong><span>Phase 1 (2025)<br \/><\/span><\/strong><span>&#8211; CMMC Level 1 (self-assessment) and Level 2 (self-assessment) required for some contracts<br \/><\/span><span>&#8211; Some contracts may require Level 2 (C3PAO assessment) audits, but it\u2019s not yet mandatory.<\/span><\/li>\n<li><strong><span>Phase 2 (2026-2027)<br \/><\/span><\/strong><span>&#8211; CMMC Level 2 (C3PAO assessment) required for many contracts handling CUI<br \/><\/span><span>&#8211; DoD may require Level 3 (DIBCAC assessment) for high-risk contracts.<\/span><\/li>\n<li><strong><span>Phase 3 (2027-2028)<br \/><\/span><\/strong><span>&#8211; CMMC Level 2 (C3PAO assessment) mandatory for all contracts handling CUI<br \/><\/span><span>&#8211; CMMC Level 3 (DIBCAC assessment) required for critical DoD programs<\/span><\/li>\n<li><strong><span>Phase 4 (2028 and beyond)<br \/><\/span><\/strong><span>&#8211; CMMC required for all new and renewed contracts\u2014no exceptions<\/span><\/li>\n<\/ul>\n<h3><span>How to Prepare: A Quick Checklist<\/span><\/h3>\n<p><span>Small businesses should take action now to avoid disruptions in their DoD contract eligibility. Follow the quick checklist below to align with the CMMC 2.0 Final Rule:<\/span><span>\u00a0<\/span><\/p>\n<ol>\n<li><strong> <\/strong><strong><span>Determine Your Required Level:<\/span><\/strong><span> Check if your contract involves FCI or CUI and what CMMC level applies.<\/span><\/li>\n<li><strong>Conduct a Self-Assessment:<\/strong> Use NIST SP 800-171\/172 controls to check gaps in cybersecurity readiness.<\/li>\n<li><strong>Develop a Compliance Plan:<\/strong> Improve security measures if Level 2 or 3 applies to your business, and find a CMMC-accredited C3PAO.<\/li>\n<li><strong>Secure Your Systems:<\/strong> Implement <a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/what-is-multifactor-authentication-e5e39437-121c-be60-d123-eda06bddf661\">multi-factor authentication (MFA)<\/a>, endpoint protection, and encryption to meet security requirements.<\/li>\n<li><strong>Train Your Team:<\/strong> Educate employees on cyber threats, secure data handling, and phishing prevention.<\/li>\n<\/ol>\n<h3>Conclusion<\/h3>\n<p>For small businesses offering professional services to the DoD, the CMMC compliance is critical. That\u2019s why these companies should start now to assess security gaps and prepare for upcoming requirements. By aligning with the upcoming CMMC 2.0 framework early, your business can remain competitive and secure DoD contracts in the future.<span>\u00a0<\/span><\/p>\n<p>The NCSS encourages businesses to adopt comprehensive security practices and stay informed about evolving cybersecurity requirements. <span>We recommend you consider becoming an NCSS member to access a wide range of our services. For more information, visit our <a href=\"https:\/\/nationalcybersecuritysociety.org\/small-business\/\">Small Business page<\/a><\/span>.<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul><\/ul>\n<\/li>\n<\/ul>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221; custom_margin=&#8221;54px|auto||auto||&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_divider _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; custom_margin=&#8221;||-2px|||&#8221; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_divider][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; header_2_font=&#8221;|600|||||||&#8221; header_2_text_color=&#8221;#00688E&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h2>References<\/h2>\n<p><a href=\"https:\/\/www.federalregister.gov\/documents\/2024\/10\/15\/2024-22905\/cybersecurity-maturity-model-certification-cmmc-program\">https:\/\/www.federalregister.gov\/documents\/2024\/10\/15\/2024-22905\/cybersecurity-maturity-model-certification-cmmc-program<\/a><\/p>\n<p><a href=\"https:\/\/dodcio.defense.gov\/cmmc\/About\/\">https:\/\/dodcio.defense.gov\/cmmc\/About\/<\/a><\/p>\n<p><a href=\"https:\/\/dodcio.defense.gov\/Portals\/0\/Documents\/CMMC\/ModelOverviewv2.pdf\">https:\/\/dodcio.defense.gov\/Portals\/0\/Documents\/CMMC\/ModelOverviewv2.pdf<\/a><\/p>\n<p><a href=\"https:\/\/isoo.blogs.archives.gov\/2020\/06\/19\/%E2%80%8Bfci-and-cui-what-is-the-difference\/\">https:\/\/isoo.blogs.archives.gov\/2020\/06\/19\/%E2%80%8Bfci-and-cui-what-is-the-difference\/<\/a><\/p>\n<p><a href=\"https:\/\/www.acquisition.gov\/far\/52.204-21\">https:\/\/www.acquisition.gov\/far\/52.204-21<\/a><\/p>\n<p><a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/171\/r3\/final\">https:\/\/csrc.nist.gov\/pubs\/sp\/800\/171\/r3\/final<\/a><\/p>\n<p><a href=\"https:\/\/csrc.nist.gov\/news\/2021\/nist-publishes-sp-800-172\">https:\/\/csrc.nist.gov\/news\/2021\/nist-publishes-sp-800-172<\/a><\/p>\n<p><a href=\"https:\/\/www.goodwinlaw.com\/en\/insights\/publications\/2024\/12\/alerts-otherindustries-the-cmmc-2-0-program-has-arrived\">https:\/\/www.goodwinlaw.com\/en\/insights\/publications\/2024\/12\/alerts-otherindustries-the-cmmc-2-0-program-has-arrived<\/a><\/p>\n<p><a href=\"https:\/\/prescientsecurity.com\/blogs\/cmmc-final-ruling-and-key-information\">https:\/\/prescientsecurity.com\/blogs\/cmmc-final-ruling-and-key-information<\/a><\/p>\n<p><a href=\"https:\/\/www.nsf.org\/ca\/en\/knowledge-library\/proposed-new-rule-cmmc-program-assessment-mechanism-implementation-plan\">https:\/\/www.nsf.org\/ca\/en\/knowledge-library\/proposed-new-rule-cmmc-program-assessment-mechanism-implementation-plan<\/a><\/p>\n<p><a href=\"https:\/\/carbidesecure.com\/resources\/cmmc-what-canadian-organizations-need-to-know\">https:\/\/carbidesecure.com\/resources\/cmmc-what-canadian-organizations-need-to-know<\/a><\/p>\n<p><a href=\"https:\/\/www.osibeyond.com\/blog\/cmmc-final-rule-timeline\/\">https:\/\/www.osibeyond.com\/blog\/cmmc-final-rule-timeline\/<\/a><\/p>\n<p><a href=\"https:\/\/ndisac.org\/dibscc\/cyberassist\/cybersecurity-maturity-model-certification\/level-1\/\">https:\/\/ndisac.org\/dibscc\/cyberassist\/cybersecurity-maturity-model-certification\/level-1\/<\/a><\/p>\n<p><a href=\"https:\/\/ndisac.org\/dibscc\/cyberassist\/cybersecurity-maturity-model-certification\/level-2\/\">https:\/\/ndisac.org\/dibscc\/cyberassist\/cybersecurity-maturity-model-certification\/level-2\/<\/a><\/p>\n<p><a href=\"https:\/\/ndisac.org\/dibscc\/cyberassist\/cybersecurity-maturity-model-certification\/level-3\/\">https:\/\/ndisac.org\/dibscc\/cyberassist\/cybersecurity-maturity-model-certification\/level-3\/<\/a><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section][et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;2px|||||&#8221; global_module=&#8221;208703&#8243; global_colors_info=&#8221;{}&#8221;][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;48px|||||&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_image src=&#8221;https:\/\/nationalcybersecuritysociety.org\/wp-content\/uploads\/2025\/09\/NCSS-3397-Bulletin-Header-Footer-Attribution-Banner-1600&#215;200-1.png&#8221; title_text=&#8221;NCSS-3397-Bulletin-Header-Footer-Attribution Banner 1600&#215;200&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; text_font_size=&#8221;8px&#8221; header_2_font=&#8221;|600|||||||&#8221; header_2_text_color=&#8221;#CCC21B&#8221; text_font_size_tablet=&#8221;13px&#8221; text_font_size_phone=&#8221;&#8221; text_font_size_last_edited=&#8221;on|tablet&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h2>About the NCSS<\/h2>\n<p><span>The National Cybersecurity Society (NCSS) is committed to improving the online safety and security of the small business community through education, awareness, and advocacy. As a 501(3)(c) organization, the NCSS uses funds from charitable donations and grants to develop educational materials, webinars, weekly cyber tips, videos, and how-to-guides. The organization\u2019s goal is to enable and empower small and medium businesses to obtain cybersecurity services, assist them in understanding their cyber risk, and advise on the type of protection needed. We want to continue to grow our community and encourage you to tell other small businesses we are here to help.<\/span><\/p>\n<p><em>The NCSS is committed to respecting the use of images in our communication efforts. Accordingly, unless otherwise specifically noted, the graphics in our bulletin are sourced under license from Adobe Stock. The header and footer images were designed and purchased through a contract with Eyedea Advertising &amp; Design Studio.<\/em><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Published: March 14, 2025Our new bulletin Cyber Threat Watch has been created to help small businesses stay up to date on the latest threats, news, and events affecting their business. The content has been curated to make cybersecurity easy and accessible for both technical and nontechnical readers.With the latest updates to the Cybersecurity Maturity Model [&hellip;]<\/p>\n","protected":false},"author":85,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"<!-- wp:divi\/placeholder \/-->","_et_gb_content_width":"","footnotes":""},"categories":[25],"tags":[],"class_list":["post-208902","post","type-post","status-publish","format-standard","hentry","category-bulletins"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CTW #17 \u2014 March 2025 - National Cybersecurity Society<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/nationalcybersecuritysociety.org\/?p=208902\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CTW #17 \u2014 March 2025 - National Cybersecurity Society\" \/>\n<meta property=\"og:description\" content=\"Published: March 14, 2025Our new bulletin Cyber Threat Watch has been created to help small businesses stay up to date on the latest threats, news, and events affecting their business. The content has been curated to make cybersecurity easy and accessible for both technical and nontechnical readers.With the latest updates to the Cybersecurity Maturity Model [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/nationalcybersecuritysociety.org\/?p=208902\" \/>\n<meta property=\"og:site_name\" content=\"National Cybersecurity Society\" \/>\n<meta property=\"article:published_time\" content=\"2025-09-15T13:30:41+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-11-12T20:44:14+00:00\" \/>\n<meta name=\"author\" content=\"Olivia Bolton\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Olivia Bolton\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/?p=208902#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/?p=208902\"},\"author\":{\"name\":\"Olivia Bolton\",\"@id\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/#\\\/schema\\\/person\\\/fe5516a3932759e8d1950572f05f30fc\"},\"headline\":\"CTW #17 \u2014 March 2025\",\"datePublished\":\"2025-09-15T13:30:41+00:00\",\"dateModified\":\"2025-11-12T20:44:14+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/?p=208902\"},\"wordCount\":1767,\"commentCount\":0,\"articleSection\":[\"Bulletins\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/?p=208902#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/?p=208902\",\"url\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/?p=208902\",\"name\":\"CTW #17 \u2014 March 2025 - National Cybersecurity Society\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/#website\"},\"datePublished\":\"2025-09-15T13:30:41+00:00\",\"dateModified\":\"2025-11-12T20:44:14+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/#\\\/schema\\\/person\\\/fe5516a3932759e8d1950572f05f30fc\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/?p=208902#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/?p=208902\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/?p=208902#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CTW #17 \u2014 March 2025\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/#website\",\"url\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/\",\"name\":\"National Cybersecurity Society\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/#\\\/schema\\\/person\\\/fe5516a3932759e8d1950572f05f30fc\",\"name\":\"Olivia Bolton\",\"url\":\"https:\\\/\\\/nationalcybersecuritysociety.org\\\/?author=85\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CTW #17 \u2014 March 2025 - National Cybersecurity Society","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/nationalcybersecuritysociety.org\/?p=208902","og_locale":"en_US","og_type":"article","og_title":"CTW #17 \u2014 March 2025 - National Cybersecurity Society","og_description":"Published: March 14, 2025Our new bulletin Cyber Threat Watch has been created to help small businesses stay up to date on the latest threats, news, and events affecting their business. The content has been curated to make cybersecurity easy and accessible for both technical and nontechnical readers.With the latest updates to the Cybersecurity Maturity Model [&hellip;]","og_url":"https:\/\/nationalcybersecuritysociety.org\/?p=208902","og_site_name":"National Cybersecurity Society","article_published_time":"2025-09-15T13:30:41+00:00","article_modified_time":"2025-11-12T20:44:14+00:00","author":"Olivia Bolton","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Olivia Bolton","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/nationalcybersecuritysociety.org\/?p=208902#article","isPartOf":{"@id":"https:\/\/nationalcybersecuritysociety.org\/?p=208902"},"author":{"name":"Olivia Bolton","@id":"https:\/\/nationalcybersecuritysociety.org\/#\/schema\/person\/fe5516a3932759e8d1950572f05f30fc"},"headline":"CTW #17 \u2014 March 2025","datePublished":"2025-09-15T13:30:41+00:00","dateModified":"2025-11-12T20:44:14+00:00","mainEntityOfPage":{"@id":"https:\/\/nationalcybersecuritysociety.org\/?p=208902"},"wordCount":1767,"commentCount":0,"articleSection":["Bulletins"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/nationalcybersecuritysociety.org\/?p=208902#respond"]}]},{"@type":"WebPage","@id":"https:\/\/nationalcybersecuritysociety.org\/?p=208902","url":"https:\/\/nationalcybersecuritysociety.org\/?p=208902","name":"CTW #17 \u2014 March 2025 - National Cybersecurity Society","isPartOf":{"@id":"https:\/\/nationalcybersecuritysociety.org\/#website"},"datePublished":"2025-09-15T13:30:41+00:00","dateModified":"2025-11-12T20:44:14+00:00","author":{"@id":"https:\/\/nationalcybersecuritysociety.org\/#\/schema\/person\/fe5516a3932759e8d1950572f05f30fc"},"breadcrumb":{"@id":"https:\/\/nationalcybersecuritysociety.org\/?p=208902#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/nationalcybersecuritysociety.org\/?p=208902"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/nationalcybersecuritysociety.org\/?p=208902#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/nationalcybersecuritysociety.org\/"},{"@type":"ListItem","position":2,"name":"CTW #17 \u2014 March 2025"}]},{"@type":"WebSite","@id":"https:\/\/nationalcybersecuritysociety.org\/#website","url":"https:\/\/nationalcybersecuritysociety.org\/","name":"National Cybersecurity Society","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/nationalcybersecuritysociety.org\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/nationalcybersecuritysociety.org\/#\/schema\/person\/fe5516a3932759e8d1950572f05f30fc","name":"Olivia Bolton","url":"https:\/\/nationalcybersecuritysociety.org\/?author=85"}]}},"_links":{"self":[{"href":"https:\/\/nationalcybersecuritysociety.org\/index.php?rest_route=\/wp\/v2\/posts\/208902","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nationalcybersecuritysociety.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nationalcybersecuritysociety.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nationalcybersecuritysociety.org\/index.php?rest_route=\/wp\/v2\/users\/85"}],"replies":[{"embeddable":true,"href":"https:\/\/nationalcybersecuritysociety.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=208902"}],"version-history":[{"count":6,"href":"https:\/\/nationalcybersecuritysociety.org\/index.php?rest_route=\/wp\/v2\/posts\/208902\/revisions"}],"predecessor-version":[{"id":209142,"href":"https:\/\/nationalcybersecuritysociety.org\/index.php?rest_route=\/wp\/v2\/posts\/208902\/revisions\/209142"}],"wp:attachment":[{"href":"https:\/\/nationalcybersecuritysociety.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=208902"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nationalcybersecuritysociety.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=208902"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nationalcybersecuritysociety.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=208902"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}